Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.20 Guidelines for dealing with information security incidents (cybersecurity incidents)

Control Overview

This control mandates that the organization creates, communicates, and maintains a structured response plan to manage suspected or confirmed security incidents affecting data availability, integrity, or confidentiality. To minimize the operational, financial, and regulatory fallout of a breach, the plan must clearly assign response roles and establish unambiguous procedures for identifying, reporting, containing, eradicating, and recovering from incidents. Furthermore, the response capability must undergo regular testing to ensure team preparedness against evolving threats.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs all incident response operations across the corporate framework and client tenant environments.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement embeds incident response deep within our ISO/IEC 27001-based ISMS, linking high-level disaster planning directly to granular technical blueprints.

Rather than maintaining a generic policy, anDREa addresses incident management through an integrated, actionable framework combining our Disaster Recovery Plan and dedicated A.05.26 - Response to information security incidents. Responsibilities are predefined across a structured response lifecycle. When an anomaly is detected, it is tracked via standardized technical workflows that govern immediate containment, forensic collection, eradication, and systematic recovery. Communication rules—including mandatory regulatory notification timelines under NIS 2 and GDPR—are codified to ensure that necessary external reporting happens rapidly, while strict internal need-to-know constraints prevent sensitive incident details from being prematurely exposed.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.24 - Information security incident management planning and preparationMandates the preparation, operational planning, and structural readiness required to respond to information security incidents.
ISO/IEC 27001A.05.26 - Response to information security incidentsDictates the technical and operational execution steps for investigating, containing, and recovering from active security breaches.
Continuity GovernanceDisaster Recovery PlanThe overarching framework detailing strategic business continuity, communication paths, and critical executive decision-making thresholds.
Operational BlueprintHow to handle incident ticketsThe step-by-step procedural manual used by technical responders to log, classify, triage, and systematically close security alerts.
Audit TrailsHistorical IR Post-Mortem LogsDocumented reports from past incidents or drills proving that the complete lifecycle—including "lessons learned" and framework corrections—is actively executed. (Issues and Risk Logging)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Core planning, operational response workflows, communication boundaries, and ticketing procedures are fully defined and active. Continuous Improvement: To continue driving maturity, maintain an active schedule of regular table-top simulations and technical drills (e.g., live ransomware or credential harvesting scenarios) to formally test responder muscle memory and satisfy evolving audit expectations.